cbcvebase.
CVE-2023-26039
published 2023-02-25

CVE-2023-26039: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33…

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.25%
65.8th percentile
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianzoneminder< zoneminder 1.36.33+dfsg1-1 (bookworm)zoneminder 1.36.33+dfsg1-1 (bookworm)
zoneminderzoneminder< 1.36.331.36.33
zoneminderzoneminder
zoneminderzoneminder>= 0 < 1.36.33+dfsg1-11.36.33+dfsg1-1
zoneminderzoneminder>= 0 < 1.36.33+dfsg1-11.36.33+dfsg1-1
zoneminderzoneminder>= 0 < 1.36.33+dfsg1-11.36.33+dfsg1-1
zoneminderzoneminder>= 1.37.00 < 1.37.331.37.33

Detection & IOCsextracted from sources · hover to see the quote

  • OS Command Injection entry point is the daemonControl() function in the ZoneMinder API controller at the path /web/api/app/Controller/HostController.php — monitor for unexpected shell-spawning processes originating from the web user via this endpoint
  • Any authenticated ZoneMinder user can trigger the injection; alert on API calls to the HostController daemonControl endpoint that include shell metacharacters or unexpected command arguments
  • ·Vulnerability is scoped as local exploitation (authenticated session required); unauthenticated remote exploitation is not directly possible — detection should focus on authenticated API abuse
  • ·Affected versions are prior to 1.36.33 and 1.37.33; Debian bullseye remains unpatched as of the advisory — prioritize detection on those deployments

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian7.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.